Privacy Policy

Last updated: April 26, 2026

Plain-language summary: we collect the minimum we need to process your order and answer your support questions. We don’t sell your data. We don’t track you across the web. Card numbers never touch our servers — Stripe handles them.

1. Who we are

WC26Cards (“we,” “us,” or “our”) operates the website at wc26cards.com as an officially authorized distributor of Panini FIFA World Cup 2026™ collectibles. You can reach us at hello@wc26cards.com.

2. What we collect

  • Order information: name, email, shipping address, phone (optional), and the items you order.
  • Reseller application information: business name, contact name, email, phone, business address, business type, monthly volume estimate, and any notes you submit.
  • Payment information: processed by Stripe. We never see, store, or transmit your card number — we receive only a token from Stripe confirming your payment succeeded, plus the last four digits and card brand for receipts.
  • Account credentials: if you’re an approved reseller, your email and a hashed password (we never see your password in plain text).
  • Anonymous usage analytics: via Vercel Analytics. Aggregated page views, country, device class. No cookies, no cross-site tracking.

3. How we use it

  • To fulfill your order and email order confirmations and shipping updates.
  • To review and respond to reseller applications.
  • To answer support questions you send us.
  • To prevent fraud and abuse (e.g. rate-limiting form submissions).
  • To comply with legal obligations (tax records, dispute response).

We do not use your data for marketing emails, retargeting ads, profile-building, or third-party data brokerage.

4. Who we share it with

Your data is shared only with these processors, each acting on our instructions:

We never sell, rent, or trade your information.

5. How long we keep it

  • Order records: 7 years (U.S. tax retention).
  • Reseller account information: until you ask us to close the account.
  • Support email threads: 2 years.
  • Declined applications: 1 year, then deleted.

6. Your rights

You can email hello@wc26cards.com any time to:

  • Request a copy of the personal data we hold about you.
  • Correct anything that’s wrong.
  • Delete your data (subject to the tax-retention period for orders).
  • Close your reseller account.

We respond within 14 days. If you’re a California resident, the same rights are extended under the CCPA. If you’re in the EU/UK, GDPR / UK-GDPR equivalents apply.

7. Security

HTTPS-only across the site (HSTS preload), strict security headers, row-level access policies on every database table, two-factor authentication on every admin account, and signed Stripe webhooks. We cannot promise absolute security on any internet-connected service, but we apply industry-standard controls. If we ever discover a breach affecting your data, we will notify you within 72 hours.

8. Cookies

We use a single first-party cookie set by Supabase Auth to keep you signed in to the reseller portal. We don’t use third-party tracking cookies or advertising pixels. Vercel Analytics is cookieless.

9. Children

Our site is intended for adults. We don’t knowingly collect data from anyone under 13. If you believe a child has submitted information, email us and we’ll delete it.

10. Changes to this policy

If we update this policy materially, we’ll change the “Last updated” date above. For changes that affect how we use existing data (not just new data), we’ll email account-holders at least 30 days before the change takes effect.

11. Contact

Questions, requests, or complaints: hello@wc26cards.com or text +1 754 230 1165.

Chat on WhatsApp